For many small and medium-sized businesses, outsourcing IT support makes perfect sense. Internal resources are stretched, cyber threats continue to increase, and having access to specialist expertise can be far more cost-effective than building an in-house team. But not all Managed Service Providers (MSPs) are created equal.
The National Cyber Security Centre (NCSC) recently published guidance to help SMEs select and work effectively with MSPs, highlighting the importance of security, transparency and clear accountability when choosing a provider. So, what should business owners be looking for?
Don’t Just Ask What They Do – Ask How They Do It
The NCSC recommends looking for recognised security accreditations such as Cyber Essentials Plus and ISO 27001. While certifications aren’t the whole story, they provide evidence that security is being taken seriously and that processes are in place to protect customer data and systems. Equally important is understanding how services are configured, monitored and maintained once they’re in place. Security isn’t just about buying the right tools – it’s about using them correctly.
Look Beyond the Sales Pitch
Case studies, testimonials and customer references can tell you far more than a polished presentation. The NCSC encourages organisations to speak to existing clients, particularly businesses of a similar size and complexity. A provider’s track record often reveals how responsive they are, how well they communicate and how effectively they handle issues when things don’t go to plan.
Make Security Responsibilities Crystal Clear
One of the biggest risks in any managed service arrangement is ambiguity. Business owners often assume their provider is taking care of everything, while the MSP assumes the customer is responsible for certain areas. The result can be dangerous gaps in protection. The NCSC advises ensuring contracts clearly define roles, responsibilities, incident reporting procedures and liability arrangements. If a cyber incident occurs, everyone should know exactly who is responsible for what.
Ask Tough Questions About Cyber Security
A reliable MSP should be comfortable discussing:
- How quickly security patches are applied
- Backup and recovery arrangements
- Multi-factor authentication (2FA/MFA)
- Security monitoring and logging
- Incident response processes
- Access controls and privileged accounts
The NCSC specifically highlights patching, backups, access management, logging and incident response as key areas SMEs should discuss before signing any contract. If your provider struggles to answer these questions clearly, consider it a warning sign.
Think About What Happens When Things Go Wrong
Nobody likes to dwell on worst-case scenarios, but resilience is often what separates good providers from great ones. How quickly will they respond to a critical incident? How will they communicate with you? What happens if they experience a cyber attack themselves? The NCSC recommends agreeing service levels, notification procedures, reporting requirements and recovery expectations upfront. SMEs should also ensure there is a clear exit strategy and defined responsibilities for managing end-of-life systems and technology.
“One of the most common misconceptions we see is that cyber security becomes someone else’s problem once you’ve outsourced IT. A good MSP should strengthen your security, but the strongest outcomes come from partnership. Both parties need a clear understanding of their responsibilities and regular conversations about risk, resilience and business priorities.” Andrew Spencer, Senior Security Consultant
Practical Advice for SMBs
Before selecting or renewing an MSP contract, take an hour to review these five questions:
- Do they hold recognised security certifications?
- Can they provide relevant customer references?
- Are responsibilities clearly documented?
- Can they explain their security processes in plain English?
- Do your service levels and reporting requirements reflect your business needs?
If the answer to any of these questions is uncertain, it’s worth taking a closer look.
The Bottom Line
An MSP can become one of your most trusted business partners, helping your organisation stay productive, secure and resilient. But choosing the right provider requires more than comparing costs and service packages. As the NCSC guidance makes clear, successful MSP relationships are built on transparency, accountability and a shared commitment to cyber security. Investing a little more time upfront could save your business a great deal of disruption later.
At Evolve North, we help organisations strengthen their cyber security through practical, proportionate support tailored to the needs of SMBs. Whether you’re reviewing an existing provider, developing your cyber security strategy, working towards Cyber Essentials, improving cyber resilience or identifying security weaknesses before they become a problem, we provide clear, actionable advice without unnecessary complexity.
If you’d like an independent conversation about your current approach to cyber security, or whether your MSP is delivering the level of assurance your business needs, contact us at info@evolvenorth.com or call 01748 905 002.
